Module 1 of the free EU AI Act Fundamentals course: what counts as an AI system under Art. 3(1), who the Act binds, extraterritorial reach, and the exclusions people miss.

The AI Act is the first horizontal AI regulation anywhere. "Horizontal" is the word that matters: it does not regulate a sector, it regulates a technology and the use it is put to. That is why a bank, a hospital and a recruitment agency can all be in scope for entirely different reasons — and why a bank can be in scope as an employer while its trading desk stays out.

This module answers three questions: what counts as an AI system, who the Act binds, and what it leaves alone.

What counts as an AI system

Art. 3(1) defines an AI system as a machine-based system that, with varying levels of autonomy and possible adaptiveness after deployment, infers from the input it receives how to generate outputs such as predictions, content, recommendations or decisions that can influence physical or virtual environments.

The load-bearing word is infers. It draws the line that most scoping exercises get wrong in both directions:

That distinction is worth money. Firms routinely declare their whole decision-engine estate as "AI" and then spend a year documenting rule sets that were never in scope. Others do the reverse and quietly exclude a scoring model because "it's just statistics" — statistical learning is squarely inside the definition.

Being an AI system is only step one. It makes the Act applicable; it says nothing yet about how much of the Act applies. That is risk classification, and it is Module 2.

Who the Act binds

The Act assigns obligations by role, not by industry. Four roles carry duties:

Role Who you are Weight of obligation
Provider You develop an AI system, or have it developed, and place it on the market or put it into service under your own name or trademark Heaviest — the full Art. 8–17 set for high-risk
Deployer You use an AI system under your own authority, in a professional capacity Lighter but real — Art. 26, and Art. 27 for some public-interest bodies
Importer You are established in the EU and place on the market a system from a third-country provider Verification duties, Art. 23
Distributor You are in the supply chain and make a system available, without being provider or importer Verification duties, Art. 24

Most financial entities assume they are deployers, and most of the time they are right. But Art. 25 turns a deployer into a provider in three situations, and every one of them is a normal commercial decision somebody makes without calling a lawyer:

  1. You put your own name or trademark on a high-risk system already on the market.
  2. You make a substantial modification to a high-risk system that is already on the market.
  3. You change the intended purpose of a system — including a non-high-risk one — such that it becomes high-risk.

Buying a vendor model, white-labelling it in your app and pointing it at a use case the vendor never described is enough to make you the provider, with the full obligation set and the vendor's cooperation duty as your only lifeline (Art. 25(4)). This is the single most expensive mistake in AI Act scoping.

Extraterritorial reach

Art. 2(1) does not ask where you are established. It catches:

A model trained and hosted in São Paulo, run by a Brazilian company, whose scores are used to decide on EU customers, is in scope. Geography of infrastructure is irrelevant; geography of effect is what counts.

What the Act leaves alone

Scope has real edges, and they are worth knowing before you inventory anything:

How it interacts with what you already comply with

The AI Act stacks; it does not replace.

Check yourself

  1. A vendor sells you a credit-decisioning model. You rebrand it as "YourBank Score" in your customer app. What are you? — A provider under Art. 25(1)(a). Putting your own trademark on a high-risk system makes you one, with the full Art. 8–17 set.
  2. Your rules engine flags transactions over €10,000 from three named countries. Is it an AI system?No. It executes conditions a human wrote; it infers nothing. Art. 3(1) is not met.
  3. Your US-based model scores EU loan applicants. Your company has no EU entity. In scope?Yes. Art. 2(1)(c): the output is used in the EU.
  4. Does excluding open-source software from Art. 2(12) mean an open-source high-risk system is unregulated?No. The exemption falls away precisely when the system is high-risk, prohibited, or caught by Art. 50.

Next: Module 2 — Risk classification: the four tiers, and why most financial AI is not high-risk →

Frequently Asked Questions

Yes, in two situations. If you place an AI system on the EU market or put it into service in the EU, you are caught as a provider regardless of where you are established. And if you are outside the EU but the OUTPUT of your system is used in the EU, Art. 2(1)(c) catches you as well. Establishment is not the test — market and output are.

No. Art. 3(1) requires a machine-based system that infers, from input, how to generate outputs, with some degree of autonomy and possible adaptiveness. A deterministic rules engine that only executes conditions a human wrote is not inferring anything and falls outside that definition. The Commission's guidelines of February 2025 confirm that simple rule-based systems are excluded.

No. They stack. The AI Act regulates the system and its lifecycle; GDPR regulates the personal data flowing through it. A compliant high-risk AI system processing personal data still needs a lawful basis, a DPIA where required, and everything else GDPR asks for.

Take compliance further with the AI Act Academy

Templates, training modules, and live Q&A — everything needed to implement AI Act compliance.